lebesgue-measure

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions facilitate the ingestion of untrusted mathematical expressions which are then executed as shell command arguments.
  • Ingestion points: Mathematical expressions are passed as string arguments to scripts/sympy_compute.py and scripts/z3_solve.py within the Tool Commands section of SKILL.md.
  • Boundary markers: No delimiters or explicit instructions to ignore embedded control characters are provided, potentially allowing an attacker to inject shell commands via the expression strings.
  • Capability inventory: The skill utilizes the Bash tool to run commands via uv run, providing a mechanism for command execution.
  • Sanitization: There is no evidence of input validation or sanitization to ensure the strings passed to the Python scripts are strictly mathematical and do not contain malicious shell sequences.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — lebesgue-measure